General

  • Target

    0cd18f67b575e8e34f59f5bd4f45b5aaa942b3273f4ba1f21b29801c11a0ff2f

  • Size

    2.3MB

  • Sample

    240626-ad64essbmh

  • MD5

    bc99531ccba4374dfc43de0be67147bc

  • SHA1

    704d8d5ca5138a58a7ec5515ac6a94c1a0c8649d

  • SHA256

    0cd18f67b575e8e34f59f5bd4f45b5aaa942b3273f4ba1f21b29801c11a0ff2f

  • SHA512

    7d2816dab2149a8ffbe19fb29be573e1dd339509392ab1f46f5d166eaa784c4d93d3db38d671273d686835a6a1b347db71b0816b3016893e71c59af08d01efcf

  • SSDEEP

    49152:fOJXmeLARxIJmJCd3npL4Nr/MQaBeyyWDg7GStLyXHxp2vy3iK5:fgXvAG4CRpUNr/MnFg7xAe4is

Score
10/10

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      0cd18f67b575e8e34f59f5bd4f45b5aaa942b3273f4ba1f21b29801c11a0ff2f

    • Size

      2.3MB

    • MD5

      bc99531ccba4374dfc43de0be67147bc

    • SHA1

      704d8d5ca5138a58a7ec5515ac6a94c1a0c8649d

    • SHA256

      0cd18f67b575e8e34f59f5bd4f45b5aaa942b3273f4ba1f21b29801c11a0ff2f

    • SHA512

      7d2816dab2149a8ffbe19fb29be573e1dd339509392ab1f46f5d166eaa784c4d93d3db38d671273d686835a6a1b347db71b0816b3016893e71c59af08d01efcf

    • SSDEEP

      49152:fOJXmeLARxIJmJCd3npL4Nr/MQaBeyyWDg7GStLyXHxp2vy3iK5:fgXvAG4CRpUNr/MnFg7xAe4is

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

2
T1497

Discovery

Query Registry

3
T1012

Virtualization/Sandbox Evasion

2
T1497

System Information Discovery

1
T1082

Tasks